Website malware scan: what an outside check can actually see

This is an outside check of your website — not an antivirus for your computer and not a file check. A website malware scan reads what your pages serve visitors now: scripts you did not add, redirects you did not set up, spam links you did not write, and whether Google or Spamhaus flagged the domain. It works from the outside: no file access, no login.

A plain-language read of what your pages serve, and what to look at first.

Free. 54 checks. No signup. No file upload.

What we check

Eight checks in the free scan read page content, third-party code and reputation. The report uses these exact names.

What you get after the check

Type a domain and the free report opens — 54 checks, no account, no access to your server. The answer sits in two groups. Content and headers names the malware signals found on the homepage: a script from a domain you do not recognise, a hidden block, redirect code, a link you did not write. Reputation shows whether the domain is in Google Web Risk or on a Spamhaus blocklist. Beside them: external resources the page loads, third-party scripts, forms posting data off your site, service files left open.

What an outside check can see

Five things a check from outside can observe, named the way your report names them. Each is a signal, not a verdict about your files.

What you seeWhat it meansWhat to do
Injected code on your pagesA script, iframe or obfuscated block you did not add, usually loaded from a domain you have never heard of.Find it in the page source, remove it, then change your admin passwords.
Hidden redirectsA visitor is sent elsewhere — sometimes only search engine crawlers are, while you still see the normal page.Check the server and CMS configuration, not just the page text.
Home page content you did not publishLinks, text or blocks you never added are on the page you show first. The check reads the home page and what the site serves publicly, not the whole site.Compare it with what you published and remove what you do not recognise.
Your domain is on a listGoogle Safe Browsing or Web Risk, or Spamhaus, already flags it: a blacklist entry that browsers and email systems act on.Establish how it got there, fix the cause, then ask for a review (steps are below).
Third-party scripts and formsOutdated or unverifiable code from other domains, or a form sending data off-site. Not an infection — an open door to one.Keep only the scripts you need, update them, post forms over HTTPS.

Is the domain on a blacklist?

Two of the eight checks read public lists; the report shows what each returned.

It is a snapshot: off the list today does not mean off the list tomorrow.

Why this is not an antivirus

The words overlap, so the two get confused, and the difference matters when a site is in trouble. A virus scan for a website and antivirus on your computer are different jobs.

A remote scan is a first look, not a diagnosis. If it shows nothing, that is not proof that the site is clean.

If your site is already flagged

A warning in front of your visitors is a symptom, not the problem. These are the owner's steps, in the order that works.

  1. Check the official status. The Security Issues section in Search Console and the Safe Browsing site status page record whether the domain is listed and why.
  2. Find out how it got there. Look at what changed recently — files, plugins and themes, admin users. Reused passwords are a common way back in.
  3. Fix the cause before asking for anything. Update or remove what was compromised and change the keys. A listing removed without this does not stay removed.
  4. Ask for a review. Once the cause is fixed, request a review in Search Console: the site is re-checked and the warning clears when it passes.

The first listing usually shows you where the door was. This check reports what it sees and files nothing on your behalf.

What the result does not prove

Better to know the edges of this check than to over-read it: what comes back is a snapshot.

No malware signals in this check is good news about what your pages served then — it is not proof that the site is clean.

How to check it yourself

Three steps, a few minutes, nothing to install.

Two listings behind our reputation checks are public: Google Web Risk and Spamhaus ZEN. Keep what you find — the URL, the script, a dated screenshot. That is what a developer needs, and what a review request is asked about.

What else the scan looks at

Malware and reputation are one part of a wider picture: the free scan runs 54 checks across the external perimeter — headers and cookies, TLS, exposed files, third-party code, login panels, subdomains, email and DNS. If your question is about email rather than the website, that side has its own check.

One boundary worth keeping: this is an outside look, not a pentest and not an audit from inside the server. Nothing is exploited or changed.

The 54-check scanHow the checks work

BlindspotScan team

We read what your public pages serve. We do not log in anywhere, do not read files, and do not attempt to remove anything we report. Checks are rate-limited per IP.

How the checks workContact us

FAQ

What does a website malware check actually look at?

It reads what your pages serve anyone who opens them: injected scripts, hidden iframes, redirects, third-party code, open service files. It opens no files and uploads nothing.

How do I check if my site is blacklisted by Google?

Open the Safe Browsing site status page and the Security Issues section in Search Console for your domain: both are official records. Our free check reads the same list through Web Risk and adds Spamhaus.

Can a remote scan find a backdoor or a web shell?

In many cases no: a backdoor or web shell is a file on your server, and an outside check sees only what the site returns to an ordinary request. It catches behaviour instead: a strange script, a redirect, a block that was not there before. Reading the files themselves takes access to the server.

Do you scan my files or need access to my server?

No. It reads only what your domain serves publicly: no login, no hosting panel access, no files from you. A file-checking service answers a different question — antivirus watches your computer, not your website.

My site is flagged, and it looks fine to me — how is that possible?

A site can serve one version to you and another to a crawler, and some content sits at a direct address. A listing can also be out of date: check the current status in Search Console.

Google started showing pages I never wrote — what does that mean?

It usually means content was added without you: spam pages or links created after a compromise, often written to push visitors to someone else's offers. Search site:yourdomain.com — this check reads the home page and what the site serves publicly, not the whole site.

Is this the same as antivirus on my computer?

No. Antivirus on your device watches programs running there; this check reads what your website serves. Email blocklists are a separate subject, covered by our DMARC check.

The 54-check scanHow the checks workWhat the paid check addsEmail authentication (DMARC) check